AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68154

CRITICAL · CVSS 9.8 EPSS 0.63%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's CRUSH (Controlled Replication Under Scalable Hashing) mapping system, specifically in the handling of bucket types during the decoding process. If exploited, a malformed CRUSH map could lead to improper indexing of the OSD weight array, potentially causing system instability or crashes. Organizations utilizing Linux systems with CRUSH for data storage should prioritize addressing this issue to maintain system integrity and prevent potential disruptions.

CVE
CVE-2026-68154
Severity
CRITICAL
CVSS
9.8
EPSS
0.63%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.